[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4385-1 dovecot -- dovecot

ID: oval:org.secpod.oval:def:603628Date: (C)2019-02-07   (M)2023-12-20
Class: PATCHFamily: unix




halfdog discovered an authentication bypass vulnerability in the Dovecot email server. Under some configurations Dovecot mistakenly trusts the username provided via authentication instead of failing. If there is no additional password verification, this allows the attacker to login as anyone else in the system. Only installations using: auth_ssl_require_client_cert = yes auth_ssl_username_from_cert = yes are affected by this flaw.

Platform:
Debian 9.x
Product:
dovecot-pgsql
dovecot-mysql
dovecot-sieve
dovecot-core
dovecot-ldap
dovecot-solr
dovecot-sqlite
dovecot-dbg
dovecot-pop3d
dovecot-imapd
dovecot-managesieved
dovecot-lucene
dovecot-gssapi
dovecot-dev
dovecot-lmtpd
Reference:
DSA-4385-1
CVE-2019-3814
CVE    1
CVE-2019-3814
CPE    3
cpe:/a:dovecot:dovecot-core
cpe:/o:debian:debian_linux:9.x
cpe:/a:dovecot:dovecot-dev

© SecPod Technologies